/?pid=hacker-discovers-adobe-pdf-back-doors-1502

Updated:11:52 AM EDT May 23


this is ggmania.com subsite Hacker Discovers Adobe PDF Back Doors - TechAmok

Hacker Discovers Adobe PDF Back Doors - [security]
05:30 PM EDT - Sep,16 2006 - post a comment

Today's exploit comes to us from Adobe Acrobat Reader. It looks as though there are a couple of backdoors in even the fully patched and latest versions. A British security researcher has figured out a way to manipulate legitimate features in Adobe PDF files to open back doors for computer attacks.  David Kierznowski, a penetration testing expert specializing in Web application testing, has released proof-of-concept code and rigged PDF files to demonstrate how the Adobe Reader program could be used to launch attacks without any user action.
The first back door (PDF), which eWEEK confirmed on a fully patched version of Adobe Reader, involves adding a malicious link to a PDF file. Once the document is opened, the target's browser is automatically launched and loads the embedded link.  At this point, it is obvious that any malicious code [can] be launched," Kierznowski said. The use of Web-based exploits to launch drive-by malware downloads is a well-known tactic and the discovery of PDF back doors is further confirmation that desktop programs have become lucrative targets for corporate espionage and other targeted attacks.

A second back door demo (PDF) presents an attack scenario that uses Adobe Systems' ADBC (Adobe Database Connectivity) and Web Services support. Kierznowski said the back door can be used to exploit a fully patched version of Adobe Professional. "The second attack accesses the Windows ODBC (on localhost), enumerates available databases and then sends this information to 'localhost' via the Web service. This attack could be expanded to perform actual database queries. Imagine attackers accessing your internal databases via a user's Web browser," he said.

Short overview of recent news articles

Windows 98 with a G41 Core 2 Duo System (May,23 2025 )

Disable These Windows Settings for Better FPS! (May,23 2025 )

I Got the Golden GPU from Dubai (May,20 2025 )

Windows 10 emergency update KB5061768 fixes BitLocker boot loops - (May,19 2025 )

2025 AUDI S5 AVANT // 0-100 100-200 TOP SPEED POV & SOUND (May,19 2025 )

Jurassic World Rebirth - Official 'Alert' Teaser Trailer (2025) (May,18 2025 )

F1 25 and F1 The Movie hand in hand (May,18 2025 )

Everyone is Cooling Their PC Wrong (May,17 2025 )

M5 KILLER? Testing the MERCEDES E63S AMG! (May,16 2025 )

Samsung Fully Reveals 5.8mm-Thick Galaxy S25 Edge (May,16 2025 )

Apple Intros New Accessibility Apps, Plus Accessibility "Labels" (May,16 2025 )

Americana - Official Trailer (2025) Sydney Sweeney, Halsey, Simon (May,16 2025 )

Aston Martin x Apple CarPlay Ultra - Next generation of automotive (May,16 2025 )

Google TAG deleted 23,000+ YouTube channels in January, February, (May,15 2025 )

NVIDIA GeForce Game Ready 576.40 WHQL Driver Released (May,14 2025 )

F1 - Official Trailer #2 (2025) Brad Pitt, Damson Idris, Kerry (May,13 2025 )

The Old Guard 2 - Official Trailer (2025) Charlize Theron, KiKi (May,11 2025 )

I think I know why Ryzen 9000 Series CPUs are Dying...(!) (May,11 2025 )

Is Windows Defender good enough in 2025? (May,10 2025 )

AMD Adrenalin 25.5.1 Driver Released for Doom: The Dark Ages (May,09 2025 )

Ripple SEC Grip OVER, XRP Freedom of USE, Market MODE BULL RUN (May,09 2025 )

"Is x86 Actually Screwed?" ft. Wendell of Level1 Techs - (May,08 2025 )

Android's New Design Guidelines Leaked (May,07 2025 )

Grand Theft Auto VI trailer #2 (May,06 2025 )

Microsoft's Dirty Secret: Your Old PC is Now Trash! (May,05 2025 )

No Noise Cancelling? GOOD. Unboxing the nwm One Headphones & First (May,04 2025 )

NEW! 2025 Audi S5 (367hp) | 0-258 km/h acceleration (May,04 2025 )

Bugatti Bolide vs Nurburgring. 1825 HorsePower Insanity (May,02 2025 )

This will be the largest tech Yard Sale EVER! Insanely low prices on (May,01 2025 )

Skoda Kodiaq RS 245 // 0-100 100-200 TOP SPEED POV & SOUND (May,01 2025 )

Disable or Uninstall Windows Recall to Protect Your Data Privacy (May,01 2025 )

A new Alternative to Nextcloud? OpenCloud presented and local (May,01 2025 )

NVIDIA GeForce Hotfix Driver 576.26 Available (Apr,29 2025 )

2025 Porsche 911 992.2 GTS T HYBRID | SOUND 0-100 100-200 200-300 & (Apr,28 2025 )

We Made Perfect Thermal Paste in a Factory, ft. Der8auer | Made In (Apr,28 2025 )

Cyber Security Company CEO Arrested for Installing Malware on (Apr,28 2025 )

This Kid Made his Own Laptop and it's AMAZING! (Apr,27 2025 )

How is this SO CHEAP? - Ubiquiti Cloud Gateway Fiber (Apr,26 2025 )

Ripple president on stablecoins, Trump and tokenization (Apr,26 2025 )

T-Mobile Launches 5G Advanced (Apr,26 2025 )

540HP BMW E46 M3 5.0 V10 // 300KMH REVIEW on AUTOBAHN (Apr,25 2025 )

Has Nvidia Given Up? (Apr,25 2025 )

AMD Software Adrenalin 25.4.1 Beta Drivers Released (Apr,23 2025 )

Stop Paying for Cloud Storage: How I Built My Own Photo Backup (Apr,23 2025 )

Wednesday: Season 2 - Official Teaser Trailer (Apr,23 2025 )

Everything You Need To Know About Windows 10 LTSC (Apr,23 2025 )

Do NOT use Distilled Water for your Water Cooling Loop! (Apr,22 2025 )

Intel Improves 285K Performance with a Big Update (Apr,22 2025 )

FERRARI 812 GTS // REVIEW on AUTOBAHN (Apr,20 2025 )

Meta Disables Apple Intelligence in Facebook and Other Apps (Apr,19 2025 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs